Skip to Content

InkBridge Networks - A new name for Network RADIUS

What Network Admins Need to Know
About BlastRADIUS 

A recorded session with the cryptographer who discovered BlastRADIUS and the engineer who built the fix.

BlastRADIUS is a CVSS 9.0 vulnerability in the RADIUS protocol - the authentication system behind millions of corporate and ISP networks worldwide. The flaw has been present in the protocol for 30 years.  

An attacker with access to the RADIUS traffic path can bypass multi-factor authentication, grant any level of network access to unknown users, and take administrative control of switches and other network equipment, all without detection. 

What you’ll learn: 

  • Why RADIUS has carried this design flaw for 30 years, and how it was discovered 

  • Which authentication methods are vulnerable - PAP, CHAP, MS-CHAPv2 - and which are safe 

  • The concrete steps to protect your network, from firmware updates to protocol-level fixes 

  • What to do right now if your network relies on non-EAP authentication methods 

About the speakers: 

Nadia Heninger is Associate Professor of cryptography at UC San Diego. She led the research team that discovered BlastRADIUS and co-authored the academic paper that named it. 

Alan DeKok is CEO of InkBridge Networks and a founder of the open-source FreeRADIUS project, the world's most widely deployed RADIUS server, authenticating hundreds of millions of users every day. He first identified this class of vulnerability in 1998 and authored an IETF RFC proposing a fix in 2007. 

Length: 50 minutes 

Fill the form to access this expert session recording: ​